
Sticky Social Link Security & Risk Analysis
wordpress.org/plugins/sticky-social-linkSticky Social Link is a Floating/Sticky Social Link Plugin. This Plugin will make Your social media links sticky/floating on your website.
Is Sticky Social Link Safe to Use in 2026?
Mostly Safe
Score 79/100Sticky Social Link is generally safe to use. 1 past CVE were resolved. Keep it updated.
The "sticky-social-link" plugin, v2.0.1, exhibits a mixed security posture. On one hand, the static analysis reveals no identified attack surface points (AJAX handlers, REST API routes, shortcodes, cron events), no dangerous functions, and all SQL queries utilize prepared statements. This suggests a well-contained codebase with good practices for database interaction. However, a significant concern is the output escaping, with only 71% of outputs being properly escaped, leaving 29% potentially vulnerable to Cross-Site Scripting (XSS) if untrusted data is ever introduced into these outputs. Taint analysis also shows no identified vulnerabilities, which is positive.
The plugin's vulnerability history is a major red flag. It has one known CVE, which is currently unpatched, and it's of medium severity, specifically an XSS vulnerability. The fact that the last vulnerability was very recent (May 7, 2024) and remains unaddressed indicates a lack of timely security patching and maintenance. This history, coupled with the less-than-perfect output escaping, strongly suggests a pattern of potential security weaknesses that are not being proactively resolved.
In conclusion, while the plugin demonstrates good internal coding practices regarding SQL and a lack of immediate attack vectors, the unpatched medium severity XSS vulnerability and the moderate rate of unescaped output are critical concerns. The recent nature of the vulnerability further exacerbates the risk, suggesting that users of this plugin are exposed to known security flaws that have not been remediated.
Key Concerns
- Currently unpatched medium severity CVE
- Moderate percentage of unescaped output
- No capability checks found
- No nonce checks found
Sticky Social Link Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Sticky Social Link <= 2.0.0 - Authenticated (Admin+) Stored Cross-Site Scripting
Sticky Social Link Code Analysis
Output Escaping
Sticky Social Link Attack Surface
WordPress Hooks 7
Maintenance & Trust
Sticky Social Link Maintenance & Trust
Maintenance Signals
Community Trust
Sticky Social Link Alternatives
IndoAge Social Share Pro
indoge-social-share-pro
Display floating social media buttons with customizable links, icons, and layouts for better engagement.
Powerkit – Supercharge your WordPress Site
powerkit
Essential components for every WordPress site: share buttons, social links, social media integrations, galleries, lazyload, custom widgets, and more.
RaraTheme Companion
raratheme-companion
23 extremely useful custom widgets to create an engaging website.
WP Social Widget
wp-social-widget
A widget to add links of social networking sites.
The Social Links
the-social-links
The Social Links plugin adds a widget and shortcode to your WordPress website allowing you to display icons linking to your social profiles.
Sticky Social Link Developer Profile
7 plugins · 2K total installs
How We Detect Sticky Social Link
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sticky-social-link/css/sslink-admin.css/wp-content/plugins/sticky-social-link/css/sslink-frontend.css/wp-content/plugins/sticky-social-link/js/sslink-admin.js/wp-content/plugins/sticky-social-link/js/sslink-admin.jssticky-social-link/css/sslink-admin.css?ver=sticky-social-link/css/sslink-frontend.css?ver=sticky-social-link/js/sslink-admin.js?ver=HTML / DOM Fingerprints
sslink-socialssslink-menu<!-- Sticky Social Link Dynamic Style -->data-tab-id